Courseiva
hardMultiple Select

CS0-003 Practice Question: Which TWO of the following are indicators of…

Which TWO of the following are indicators of potential data exfiltration via DNS?

⚠ Common exam trap

CompTIA often tests the distinction between DNS tunneling indicators (TXT record volume and long subdomains) and other DNS anomalies like NXDOMAIN responses, which are more associated with DGA or reconnaissance rather than exfiltration.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

High volume of TXT record queries

TXT records are commonly used in DNS tunneling to encode exfiltrated data. Attackers embed data in TXT record queries or responses, and a high volume of such queries is a strong indicator of data exfiltration via DNS.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Unusual TLS handshake patterns

    Why it's wrong here

    While anomalies in TLS handshakes can indicate encrypted command-and-control (C2) communication or data exfiltration over HTTPS, they occur at the transport and presentation layers and are entirely separate from the DNS protocol. DNS queries typically run over UDP port 53 without TLS, unless DNS-over-TLS (DoT) is specifically configured, making TLS handshake patterns irrelevant to standard DNS exfiltration detection.

  • ✗

    Traffic to known malicious IPs over HTTP

    Why it's wrong here

    Direct HTTP traffic to known malicious IP addresses indicates web-based command-and-control (C2) activity or standard web-based data exfiltration. This type of traffic does not leverage the DNS protocol as a covert channel, which is the primary mechanism for DNS-based exfiltration where data is embedded within queries to authoritative nameservers.

  • ✗

    Large number of NXDOMAIN responses

    Why it's wrong here

    A high volume of NXDOMAIN (Non-Existent Domain) responses typically points to malware utilizing Domain Generation Algorithms (DGAs) to locate active C2 servers, or aggressive network scanning. While suspicious, it indicates a failure to resolve domains rather than the successful, bidirectional data transfer characteristic of active DNS exfiltration.

  • ✓

    High volume of TXT record queries

    Why this is correct

    Attackers frequently abuse DNS TXT records because they can hold large, arbitrary strings of text, making them ideal for carrying payload data or receiving commands. A sudden spike in TXT queries, especially to unfamiliar external domains, strongly suggests that an internal host is using these records to bypass traditional firewalls and exfiltrate sensitive data.

  • ✓

    Frequent queries to long subdomains

    Why this is correct

    DNS exfiltration techniques often prepend encoded data (such as Base64 strings) to the domain name as a subdomain, resulting in unusually long and complex query strings. When these queries reach the attacker's authoritative nameserver, the server decodes the subdomain portion to reconstruct the stolen data, making frequent queries to long subdomains a primary indicator of compromise.

Visual reference

Client Recursive Resolver Root DNS (13 root servers) TLD DNS (.com, .org, …) Authoritative example.com query IP addr answer

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.